CVE-2018-5156 PUBLISHED

A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result in stream data being cast to the wrong type causing a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

EPSS 3.11% · 86.7th percentile

Risk Scores

EPSS Score
3.11%
86.7th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSfirefox60.0.2+build1-0ubuntu0.16.04.1, 58.0.1+build1-0ubuntu0.16.04.1, 58.0.2+build1-0ubuntu0.16.04.1
Ubuntu:18.04:LTSfirefox56.0+build6-0ubuntu1, 57.0.1+build2-0ubuntu1, 59.0.1+build1-0ubuntu1
Ubuntu:14.04:LTSfirefox52.0.2+build1-0ubuntu0.14.04.1, 53.0+build6-0ubuntu0.14.04.1, 53.0.2+build1-0ubuntu0.14.04.2

Timeline

References

Open in Interactive Console →